Cubist Role Access Tokens API

The Role Access Tokens API from Cubist — 2 operation(s) for role access tokens.

OpenAPI Specification

cubist-role-access-tokens-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: CubeSigner Account Role Access Tokens API
  description: The CubeSigner management and signing service.
  contact:
    name: Cubist Inc.
    email: hello@cubist.dev
  version: v0.1.0
servers:
- url: https://gamma.signer.cubist.dev
  description: Testing and staging environment
- url: https://prod.signer.cubist.dev
  description: Production environment
security:
- Cognito: []
tags:
- name: Role Access Tokens
paths:
  /v0/org/{org_id}/roles/{role_id}/tokens:
    post:
      tags:
      - Role Access Tokens
      summary: Create Token
      description: 'Create Token


        Creates a new access token for a given role (to be used as "API Key" for all signing actions).

        The `restricted_actions` field on the [Role] determines the membership role that is required to

        create tokens.'
      operationId: createRoleToken
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      - name: role_id
        in: path
        description: Name or ID of the desired Role
        required: true
        schema:
          type: string
        example: Role#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateTokenRequest'
        required: true
      responses:
        '200':
          $ref: '#/components/responses/NewSessionResponse'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:session:create
  /v0/org/{org_id}/token/keys:
    get:
      tags:
      - Role Access Tokens
      summary: Get Token-Accessible Keys
      description: 'Get Token-Accessible Keys


        Retrieves the keys that a user or role session can access.'
      operationId: listTokenKeys
      parameters:
      - name: org_id
        in: path
        description: Name or ID of the desired Org
        required: true
        schema:
          type: string
        example: Org#124dfe3e-3bbd-487d-80c0-53c55e8ab87a
      responses:
        '200':
          $ref: '#/components/responses/KeyInfos'
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
      - SignerAuth:
        - manage:key:get
components:
  schemas:
    EpochDateTime:
      type: integer
      format: int64
      description: 'DateTime measured in seconds since unix epoch.

        A wrapper type for serialization that encodes a [`SystemTime`] as a [`u64`]

        representing the number of seconds since [`SystemTime::UNIX_EPOCH`].'
      minimum: 0
    MfaRequiredArgs:
      type: object
      required:
      - id
      - ids
      - org_id
      properties:
        id:
          type: string
          description: Always set to first MFA id from `Self::ids`
        ids:
          type: array
          items:
            type: string
            minLength: 1
          description: Non-empty MFA request IDs
        org_id:
          type: string
          description: Organization id
        policy_eval_tree:
          description: Optional policy evaluation tree (included in signer responses, when requested)
          nullable: true
        session:
          allOf:
          - $ref: '#/components/schemas/NewSessionResponse'
          nullable: true
    B32:
      type: string
      description: Wrapper around a zeroizing 32-byte fixed-size array
    KeyDerivationInfo:
      type: object
      description: Derivation-related metadata for keys derived from a long-lived mnemonic
      required:
      - mnemonic_id
      - derivation_path
      properties:
        derivation_path:
          type: string
          description: The derivation path used to derive this key
        mnemonic_id:
          type: string
          description: The mnemonic-id of the key's parent mnemonic
    CoinbaseApiPropertiesPatch:
      type: object
      description: 'Wire-format patch payload for [`KeyProperties::CoinbaseApi`].


        Every field follows the same per-field PATCH semantics: a missing field

        leaves the existing value alone, a JSON `null` clears it, and a value sets it.'
      properties:
        api_key_id:
          type: string
          description: 'Identifier of the Coinbase API key this key authenticates as. Plain

            (non-secret) value; appears in JWT `kid`/`sub` claims.'
          nullable: true
        portfolio_name:
          type: string
          description: Coinbase portfolio name.
          nullable: true
        portfolio_uuid:
          type: string
          description: Coinbase portfolio UUID.
          nullable: true
    ScopeSet:
      oneOf:
      - type: string
        description: All scopes
        enum:
        - All
      - type: object
        required:
        - AllExcept
        properties:
          AllExcept:
            type: array
            items:
              $ref: '#/components/schemas/Scope'
            description: All scopes except these (including those transitively implied).
      - type: object
        required:
        - AllOf
        properties:
          AllOf:
            type: array
            items:
              $ref: '#/components/schemas/Scope'
            description: All of these scopes (including those transitively implied).
      description: A set of scopes.
    CommonFields:
      allOf:
      - type: object
        description: 'Versioning fields (e.g., version number, creation time, and last modified times)

          that are common to different types of resources.'
        properties:
          created:
            allOf:
            - $ref: '#/components/schemas/EpochDateTime'
            nullable: true
          last_modified:
            allOf:
            - $ref: '#/components/schemas/EpochDateTime'
            nullable: true
          version:
            type: integer
            format: int64
            description: Version of this object
            minimum: 0
      - type: object
        properties:
          edit_policy:
            $ref: '#/components/schemas/EditPolicy'
          metadata:
            description: 'User-defined metadata. When rendering (e.g., in the browser) you should treat

              it as untrusted user data (and avoid injecting metadata into HTML directly) if

              untrusted users can create/update keys (or their metadata).'
      description: 'Fields that are common to different types of resources such as keys, roles, etc.

        Includes versioning fields plus metadata, edit policy, etc.'
    AcceptedValue:
      oneOf:
      - type: object
        required:
        - SignDryRun
        properties:
          SignDryRun:
            $ref: '#/components/schemas/SignDryRunArgs'
      - type: object
        required:
        - BinanceDryRun
        properties:
          BinanceDryRun:
            $ref: '#/components/schemas/BinanceDryRunArgs'
      - type: object
        required:
        - BybitDryRun
        properties:
          BybitDryRun:
            $ref: '#/components/schemas/BybitDryRunArgs'
      - type: object
        required:
        - CoinbaseDryRun
        properties:
          CoinbaseDryRun:
            $ref: '#/components/schemas/CoinbaseDryRunArgs'
      - type: object
        required:
        - MfaRequired
        properties:
          MfaRequired:
            $ref: '#/components/schemas/MfaRequiredArgs'
      description: Different responses we return for success status codes.
    RatchetConfig:
      type: object
      properties:
        auth_lifetime:
          type: integer
          format: int64
          description: 'The lifetime (in seconds) of auth tokens for this session.

            Auth tokens can be refreshed (renewed) using a valid (unexpired)

            refresh token, but not beyond the session lifetime.'
          default: 300
          example: 3600
          minimum: 0
        grace_lifetime:
          type: integer
          format: int64
          description: 'The amount of time (in seconds) that an auth token for this session remains

            valid after it has been refreshed and a new auth token has been issued. This

            helps to address concurrency hazards, for example, if one thread makes requests

            with auth token while another refreshes it.'
          default: 30
          example: 30
          minimum: 0
        refresh_lifetime:
          type: integer
          format: int64
          description: 'The lifetime (in seconds) of refresh tokens for this session.

            If this value is shorter than the session lifetime, inactive sessions

            will become invalid once the auth and refresh tokens have both expired.'
          default: 86400
          example: 43200
          minimum: 0
        session_lifetime:
          type: integer
          format: int64
          description: 'The lifetime (in seconds) of the session.

            The session cannot be extended beyond its original lifetime.'
          default: 31536000
          example: 86400
          minimum: 0
    NotFoundErrorCode:
      type: string
      enum:
      - UriSegmentMissing
      - UriSegmentInvalid
      - TotpNotConfigured
      - FidoKeyNotFound
      - FidoChallengeNotFound
      - TotpChallengeNotFound
      - UserExportRequestNotFound
      - UserExportCiphertextNotFound
      - OrgExportCiphertextNotFound
      - UploadObjectNotFound
      - PolicySecretNotFound
      - BucketMetaNotFound
      - TimestreamDisabled
      - CustomChainNotFound
      - InvitationNotFound
      - TransactionNotFound
      - EmailConfigNotFound
    HttpRequestCmp:
      oneOf:
      - type: string
        description: The requests must match exactly. Any given MFA receipt can be used at most once.
        enum:
        - Eq
      - type: object
        required:
        - EvmTx
        properties:
          EvmTx:
            $ref: '#/components/schemas/EvmTxCmp'
      - type: object
        required:
        - SolanaTx
        properties:
          SolanaTx:
            $ref: '#/components/schemas/SolanaTxCmp'
      description: How to compare HTTP requests when verifying MFA receipt (see [MfaRequest::verify_request])
    BadGatewayErrorCode:
      type: string
      enum:
      - Generic
      - CustomChainRpcError
      - EsploraApiError
      - SentryApiError
      - CallWebhookError
      - OAuthProviderError
      - OidcDisoveryFailed
      - OidcIssuerJwkEndpointUnavailable
      - SmtpServerUnavailable
    SolanaTxCmp:
      type: object
      properties:
        ignore_blockhash:
          type: boolean
          description: Whether the 'recent_blockhash' property of the Solana transaction is allowed to be different.
    InternalErrorCode:
      type: string
      enum:
      - NoMaterialId
      - InvalidAuditLogEntry
      - UnexpectedCheckerRule
      - UnresolvedPolicyReference
      - UnexpectedAclAction
      - FidoKeyAssociatedWithMultipleUsers
      - ClaimsParseError
      - InvalidThrottleId
      - InvalidEmailAddress
      - EmailTemplateRender
      - OidcIdentityHeaderMissing
      - OidcIdentityParseError
      - SystemTimeError
      - PasswordHashParseError
      - SendMailError
      - ReqwestError
      - EmailConstructionError
      - TsWriteError
      - TsQueryError
      - DbQueryError
      - DbGetError
      - DbDeleteError
      - DbPutError
      - DbUpdateError
      - SerdeError
      - TestAndSetError
      - DbGetItemsError
      - DbWriteError
      - CubistSignerError
      - CwListMetricsError
      - CwPutMetricDataError
      - GetAwsSecretError
      - SecretNotFound
      - KmsGenerateRandomError
      - MalformedTotpBytes
      - KmsGenerateRandomNoResponseError
      - CreateKeyError
      - ParseDerivationPathError
      - SplitSignerError
      - CreateImportKeyError
      - CreateEotsNoncesError
      - EotsSignError
      - BabylonCovSignError
      - CognitoDeleteUserError
      - CognitoListUsersError
      - CognitoGetUserError
      - MissingUserEmail
      - CognitoResendUserInvitation
      - CognitoSetUserPasswordError
      - GenericInternalError
      - AssumeRoleWithoutEvidence
      - OidcAuthWithoutOrg
      - MissingKeyMetadata
      - KmsEnableKeyError
      - KmsDisableKeyError
      - LambdaInvokeError
      - LambdaNoResponseError
      - LambdaFailure
      - LambdaUnparsableResponse
      - SerializeEncryptedExportKeyError
      - DeserializeEncryptedExportKeyError
      - ReEncryptUserExport
      - S3UploadError
      - S3DownloadError
      - S3CopyError
      - S3ListObjectsError
      - S3DeleteObjectsError
      - S3BuildError
      - S3PresignedUrlError
      - ManagedStateMissing
      - InternalHeaderMissing
      - InvalidInternalHeaderValue
      - RequestLocalStateAlreadySet
      - OidcOrgMismatch
      - OidcIssuerInvalidJwk
      - InvalidPkForMaterialId
      - SegwitTweakFailed
      - UncheckedOrg
      - SessionOrgIdMissing
      - AvaSignCredsMissing
      - AvaSignSignatureMissing
      - ExpectedRoleSession
      - InvalidThirdPartyIdentity
      - CognitoGetUser
      - SnsSubscribeError
      - SnsUnsubscribeError
      - SnsGetSubscriptionAttributesError
      - SnsSubscriptionAttributesMissing
      - SnsSetSubscriptionAttributesError
      - SnsPublishBatchError
      - InconsistentMultiValueTestAndSet
      - MaterialIdError
      - InvalidBtcAddress
      - HistoricalTxBodyMissing
      - InvalidOperation
      - ParentOrgNotFound
      - OrgParentLoop
      - ResolvedParentOrgWithNoScopeCeiling
      - InvalidUploadObjectId
      - PolicyEngineNotFound
      - PolicyEngineError
      - PolicySecretsEncryptionError
      - CreatePolicyImportKeyError
      - InvalidAlias
      - EmptyUpdateModifiedObject
      - EmptyUpdateModifiedActions
      - DbContactAddressesInvalid
      - InvalidEvmSigedRlp
      - InvalidErc20Data
      - InvalidRpcUrl
    SignerErrorCode:
      oneOf:
      - $ref: '#/components/schemas/SignerErrorOwnCodes'
      - $ref: '#/components/schemas/AcceptedValueCode'
      - $ref: '#/components/schemas/BadRequestErrorCode'
      - $ref: '#/components/schemas/BadGatewayErrorCode'
      - $ref: '#/components/schemas/NotFoundErrorCode'
      - $ref: '#/components/schemas/ForbiddenErrorCode'
      - $ref: '#/components/schemas/UnauthorizedErrorCode'
      - $ref: '#/components/schemas/PreconditionErrorCode'
      - $ref: '#/components/schemas/TimeoutErrorCode'
      - $ref: '#/components/schemas/ConflictErrorCode'
      - $ref: '#/components/schemas/InternalErrorCode'
    EvmTxCmp:
      type: object
      properties:
        grace:
          type: integer
          format: int64
          description: 'To prevent replay attacks, any given MFA receipt is normally allowed to be used only once.


            In this case, however, because EVM transactions already have a replay prevention mechanism

            (namely the ''nonce'' property), we allow the user to specify a grace period (in seconds) to

            indicate how long an MFA receipt should remain valid after its first use.


            Note that we allow both ''grace'' and ''ignore_nonce'' to be set because once an MFA request

            enters its grace period we unconditionally set its ''ignore_nonce'' property to ''false'' to

            ensure that any subsequent requests that claim the same receipt must sign for the same

            nonce as the request we signed originally with that receipt.


            Also note that the grace period cannot extend the lifetime of an MFA request beyond its

            original expiration date.


            The grace period must not be greater than 30 days.'
          nullable: true
          minimum: 0
        ignore_gas:
          type: boolean
          description: Whether the 'gas' property of the EVM transaction is allowed to be different.
        ignore_nonce:
          type: boolean
          description: Whether the 'nonce' property of the EVM transaction is allowed to be different.
    EvmTxDepositErrorCode:
      type: string
      enum:
      - EvmTxDepositReceiverMismatch
      - EvmTxDepositEmptyData
      - EvmTxDepositEmptyChainId
      - EvmTxDepositEmptyReceiver
      - EvmTxDepositUnexpectedValue
      - EvmTxDepositUnexpectedDataLength
      - EvmTxDepositNoAbi
      - EvmTxDepositNoDepositFunction
      - EvmTxDepositUnexpectedFunctionName
      - EvmTxDepositUnexpectedValidatorKey
      - EvmTxDepositInvalidValidatorKey
      - EvmTxDepositMissingDepositArg
      - EvmTxDepositWrongDepositArgType
      - EvmTxDepositValidatorKeyNotInRole
      - EvmTxDepositUnexpectedWithdrawalCredentials
      - EvmTxDepositUnresolvedRole
      - EvmTxDepositInvalidDepositEncoding
    KeyInfo:
      allOf:
      - $ref: '#/components/schemas/CommonFields'
      - type: object
        required:
        - key_type
        - key_id
        - material_id
        - purpose
        - enabled
        - owner
        - public_key
        - policy
        properties:
          derivation_info:
            allOf:
            - $ref: '#/components/schemas/KeyDerivationInfo'
            nullable: true
          enabled:
            type: boolean
            description: Whether the key is enabled (only enabled keys may be used for signing)
          key_id:
            type: string
            description: 'The id of the key: "Key#" followed by a unique identifier specific to

              the type of key (such as a public key for BLS or an ethereum address for Secp)'
            example: Key#0x8e3484687e66cdd26cf04c3647633ab4f3570148
          key_type:
            $ref: '#/components/schemas/KeyType'
          material_id:
            type: string
            description: A unique identifier specific to the type of key, such as a public key or an ethereum address
            example: '0x8e3484687e66cdd26cf04c3647633ab4f3570148'
          owner:
            type: string
            description: Owner of the key
            example: User#c3b9379c-4e8c-4216-bd0a-65ace53cf98f
          policy:
            type: array
            items: {}
            description: Key policy
            example:
            - AllowRawBlobSigning
            - RequireMfa:
                count: 1
          properties:
            allOf:
            - $ref: '#/components/schemas/KeyPropertiesPatch'
            nullable: true
          provenance:
            type: string
            description: The key provenance.
            nullable: true
          public_key:
            type: string
            description: 'Hex-encoded, serialized public key. The format used depends on the key type:

              - Secp256k1 keys use 65-byte uncompressed SECG format;

              - Stark keys use 33-byte compressed SECG format;

              - BLS keys use 48-byte compressed BLS12-381 (ZCash) format;

              - Ed25519 keys use the canonical 32-byte encoding specified in RFC 8032.'
            example: '0x04d2688b6bc2ce7f9879b9e745f3c4dc177908c5cef0c1b64cff19ae7ff27dee623c64fe9d9c325c7fbbc748bbd5f607ce14dd83e28ebbbb7d3e7f2ffb70a79431'
          purpose:
            type: string
            description: The purpose for which the key can be used (e.g., chain id for which the key is allowed to sign messages)
            example: Eth2Validator(1)
          region:
            type: string
            description: The region affinity for this key
    EditPolicy:
      type: object
      description: 'A policy which governs when and who is allowed to update the entity this policy is

        attached to (e.g., a role or a key).


        When attached to a role, by default, this policy applies to role deletion and all

        role updates (including adding/removing keys and users); in terms of scopes,

        it applies to `manage:role:update:*` and `manage:role:delete`.


        When attached to a key, by default, this policy applies to key deletion, all

        key updates, and adding/removing that key to/from a role; in terms of scopes,

        it applies to `manage:key:update:*`, `manage:key:delete`, `manage:role:update:key:*`.


        This default can be changed by setting the `applies_to_scopes` property.'
      properties:
        applies_to_scopes:
          $ref: '#/components/schemas/ScopeSet'
        mfa:
          allOf:
          - $ref: '#/components/schemas/MfaPolicy'
          nullable: true
        time_lock_until:
          allOf:
          - $ref: '#/components/schemas/EpochDateTime'
          nullable: true
    OperationKind:
      type: string
      description: All different kinds of sensitive operations
      enum:
      - AvaSign
      - AvaChainTxSign
      - BabylonCovSign
      - BabylonRegistration
      - BabylonStaking
      - BinanceSubToMaster
      - BinanceSubToSub
      - BinanceUniversalTransfer
      - BinanceSubAccountAssets
      - BinanceAccountInfo
      - BinanceSubAccountTransferHistory
      - BinanceUniversalTransferHistory
      - BinanceWithdraw
      - BinanceWithdrawHistory
      - BinanceDeposit
      - BinanceDepositHistory
      - BinanceListSubAccounts
      - BinanceCoinInfo
      - BlobSign
      - BtcMessageSign
      - BtcSign
      - BybitQueryUser
      - BybitQuerySubMembers
      - BybitQueryCoinsBalance
      - BybitQueryDepositAddress
      - BybitUniversalTransfer
      - BybitWithdraw
      - BybitWithdrawals
      - CoinbaseListAccounts
      - CoinbaseListPortfolios
      - CoinbaseMoveFunds
      - DiffieHellman
      - PsbtSign
      - TaprootSign
      - Eip191Sign
      - Eip712Sign
      - Eip7702Sign
      - EotsNonces
      - EotsSign
      - Eth1Sign
      - Eth2Sign
      - Eth2Stake
      - Eth2Unstake
      - SolanaSign
      - SuiSign
      - TendermintSign
      - RoleUpdate
    ErrorResponse:
      type: object
      description: The structure of ErrorResponse must match the response template that AWS uses
      required:
      - message
      - error_code
      properties:
        accepted:
          allOf:
          - $ref: '#/components/schemas/AcceptedValue'
          nullable: true
        error_code:
          $ref: '#/components/schemas/SignerErrorCode'
        message:
          type: string
          description: Error message
        policy_eval_tree:
          description: Optional policy evaluation tree (included in signer responses, when requested)
          nullable: true
        request_id:
          type: string
          description: Optional request identifier
    PreconditionErrorOwnCodes:
      type: string
      enum:
      - FailOnMfaRequired
      - KeyRegionLocked
      - KeyRegionChangedRecently
      - MfaRegionLocked
      - Eth2ProposerSlotTooLow
      - Eth2AttestationSourceEpochTooLow
      - Eth2AttestationTargetEpochTooLow
      - Eth2ConcurrentBlockSigning
      - Eth2ConcurrentAttestationSigning
      - Eth2MultiDepositToNonGeneratedKey
      - Eth2MultiDepositUnknownInitialDeposit
      - Eth2MultiDepositWithdrawalAddressMismatch
      - ConcurrentSigningWhenTimeLimitPolicyIsDefined
      - BabylonEotsConcurrentSigning
      - TendermintStateError
      - TendermintConcurrentSigning
      - MfaApprovalsNotYetValid
    ClientSessionInfo:
      type: object
      description: 'Session information sent to the client.

        This struct works in tandem with its server-side counterpart [`SessionData`].'
      required:
      - session_id
      - auth_token
      - refresh_token
      - epoch
      - epoch_token
      - auth_token_exp
      - refresh_token_exp
      properties:
        auth_token:
          type: string
          description: Token to use for authorization.
        auth_token_exp:
          $ref: '#/components/schemas/EpochDateTime'
        epoch:
          type: integer
          format: int32
          description: Epoch at which the token was last refreshed
          minimum: 0
        epoch_token:
          $ref: '#/components/schemas/B32'
        refresh_token:
          type: string
          description: Token to use for refreshing the `(auth, refresh)` token pair
        refresh_token_exp:
          $ref: '#/components/schemas/EpochDateTime'
        session_id:
          type: string
          description: Session ID
    PolicyErrorOwnCodes:
      type: string
      enum:
      - Inapplicable
      - SuiTxReceiversDisallowedTransactionKind
      - SuiTxReceiversDisallowedTransferAddress
      - SuiTxReceiversDisallowedCommand
      - BtcTxDisallowedOutputs
      - BtcSignatureExceededValue
      - BtcValueOverflow
      - BtcSighashTypeDisallowed
      - Eip7702AddressMismatch
      - EvmTxReceiverMismatch
      - EvmTxChainIdMismatch
      - EvmTxSenderMismatch
      - EvmTxExceededValue
      - EvmTxExceededGasCost
      - EvmTxGasCostUndefined
      - EvmDataDisallowed
      - Erc20DataInvalid
      - EvmContractAddressUndefined
      - EvmContractChainIdUndefined
      - EvmDataNotDefined
      - EvmDataInvalid
      - EvmContractNotInAllowlist
      - Erc20ExceededTransferLimit
      - Erc20ReceiverMismatch
      - Erc20ExceededApproveLimit
      - Erc20SpenderMismatch
      - EvmFunctionNotInAllowlist
      - EvmFunctionCallInvalid
      - EvmFunctionCallDisallowedArg
      - PolicyDisjunctionError
      - PolicyNegationError
      - Eth2ExceededMaxUnstake
      - Eth2ConcurrentUnstaking
      - NotInIpv4Allowlist
      - NotInOriginAllowlist
      - NotInOperationAllowlist
      - InvalidSourceIp
      - RawSigningNotAllowed
      - DiffieHellmanExchangeNotAllowed
      - Eip712SigningNotAllowed
      - OidcSourceNotAllowed
      - NoOidcAuthSourcesDefined
      - AddKeyToRoleDisallowed
      - KeysAlreadyInRole
      - KeyInMultipleRoles
      - KeyAccessError
      - RequireRoleSessionKeyAccessError
      - BtcMessageSigningNotAllowed
      - Eip191SigningNotAllowed
      - Eip7702SigningNotAllowed
      - TaprootSigningDisallowed
      - SegwitSigningDisallowed
      - PsbtSigningDisallowed
      - BabylonStakingDisallowed
      - TimeLocked
      - CelPolicyDenied
      - BabylonStakingNetwork
      - BabylonStakingParamsVersion
      - BabylonStakingExplicitParams
      - BabylonStakingStakerPk
      - BabylonStakingFinalityProviderPk
      - BabylonStakingLockTime
      - BabylonStakingValue
      - BabylonStakingChangeAddress
      - BabylonStakingFee
      - BabylonStakingWithdrawalAddress
      - BabylonStakingBbnAddress
      - SolanaInstructionCountLow
      - SolanaInstructionCountHigh
      - SolanaNotInInstructionAllowlist
      - SolanaInstructionMismatch
      - WasmPoliciesDisabled
      - WasmPolicyDenied
      - WasmPolicyFailed
      - WebhookPoliciesDisabled
      - DeniedByWebhook
      - ExplicitlyDenied
    ExplicitScope:
      type: string
      title: ExplicitScope
      description: Explicitly named scopes for accessing CubeSigner APIs
      enum:
      - sign:*
      - sign:ava
      - sign:binance:*
      - sign:binance:subToMaster
      - sign:binance:subToSub
      - sign:binance:universalTransfer
      - sign:binance:subAccountAssets
      - sign:binance:accountInfo
      - sign:binance:subAccountTransferHistory
      - sign:binance:universalTransferHistory
      - sign:binance:withdraw
      - sign:binance:withdrawHistory
      - sign:binance:deposit
      - sign:binance:depositHistory
      - sign:binance:listSubAccounts
      - sign:binance:coinInfo
      - sign:bybit:*
      - sign:bybit:queryUser
      - sign:bybit:querySubMembers
      - sign:bybit:queryCoinsBalance
      - sign:bybit:queryDepositAddress
      - sign:bybit:universalTransfer
      - sign:bybit:withdraw
      - sign:bybit:withdrawals
      - sign:coinbase:*
      - sign:coinbase:accounts:list
      - sign:coinbase:portfolios:list
      - sign:coinbase:funds:move
      - sign:blob
      - sign:diffieHellman
      - sign:btc:*
      - sign:btc:segwit
      - sign:btc:taproot
      - sign:btc:psbt:*
      - sign:btc:psbt:doge
      - sign:btc:psbt:legacy
      - sign:btc:psbt:segwit
      - sign:btc:psbt:taproot
      - sign:btc:psbt:ltcSegwit
      - sign:btc:message:*
      - sign:btc:message:segwit
      - sign:btc:message:legacy
      - sign:babylon:*
      - sign:babylon:eots:*
      - sign:babylon:eots:nonces
      - sign:babylon:eots:sign
      - sign:babylon:staking:*
      - sign:babylon:staking:deposit
      - sign:babylon:staking:unbond
      - sign:babylon:staking:withdraw
      - sign:babylon:staking:slash
      - sign:babylon:registration
      - sign:babylon:covenant
      - sign:evm:*
      - sign:evm:tx
      - sign:evm:eip191
      - sign:evm:eip712
      - sign:evm:eip7702
      - sign:eth2:*
      - sign:eth2:validate
      - sign:eth2:stake
      - sign:eth2:unstake
      - sign:solana
      - sign:sui
      - sign:tendermint
      - sign:mmi
      - manage:*
      - manage:readonly
      - manage:email:*
      - manage:email:get
      - manage:email:update
      - manage:email:delete
      - manage:mfa:*
      - manage:mfa:readonly
      - manage:mfa:list
      - manage:mfa:vote:*
      - manage:mfa:vote:cs
      - manage:mfa:vote:email
      - manage:mfa:vote:fido
      - manage:mfa:vote:totp
      - manage:mfa:register:*
      - manage:mfa:register:fido
      - manage:mfa:register:totp
      - manage:mfa:register:email
      - manage:mfa:unregister:*
      - manage:mfa:unregister:fido
      - manage:mfa:unregister:totp
      - manage:mfa:verify:*
      - manage:mfa:verify:totp
      - manage:key:*
      - manage:key:readonly
      - manage:key:get
      - manage:key:attest
      - manage:key:listRoles
      - manage:key:list
      - manage:key:history:tx:list
      - manage:key:create
      - manage:key:import
      - manage:key:update:*
      - manage:key:update:owner
      - manage:key:update:policy
      - manage:key:update:enabled
      - manage:key:update:region
      - manage:key:update:metadata
      - manage:key:update:properties
      - manage:key:update:editPolicy
      - manage:key:delete
      - manage:policy:*
      - manage:policy:readonly
      - manage:policy:create
      - manage:policy:get
      - manage:policy:list
      - manage:policy:delete
      - manage:policy:update:*
      - manage:policy:update:owner
      - manage:policy:update:name
      - manage:policy:update:acl
      - manage:policy:update:editPolicy
      - manage:policy:update:metadata
      - manage:policy:update:rule
      - manage:policy:invoke
      - manage:policy:wasm:*
      - manage:policy:wasm:upload
      - manage:policy:secrets:*
      - manage:policy:secrets:get
      - manage:policy:secrets:update:*
      - manage:policy:secrets:update:values
      - manage:policy:secrets:update:acl
      - manage:policy:secrets:update:editPolicy
      - manage:policy:buckets:*
      - manage:policy:buckets:get
      - manage:policy:buckets:list
      - manage:policy:buckets:update:*
      - manage:policy:buckets:update:owner
      - manage:policy:buckets:update:acl
      - manage:policy:buckets:update:metadata
      - manage:contact:*
      - manage:contact:readonly
      - manage:contact:create
      - manage:contact:get
      - manage:contact:list
      - manage:contact:delete
      - manage:contact:update:*
      - manage:contact:update:name
      - manage:contact:update:addresses
      - manage:contact:update:owner
      - manage:contact:update:labels
      - manage:contact:update:metadata
      - manage:contact:update:editPolicy
      - manage:contact:lookup:*
      - manage:contact:lookup:address
      - manage:policy:createImportKey
      - manage:role:*
      - manage:role:readonly
      - manage:role:create
      - manage:role:delete
      - manage:role:get:*
      - manage:role:attest
      - manage:role:get:keys
      - manage:role:get:keys:list
      - manage:role:get:keys:get
      - manage:role:get:users
      - manage:role:list
      - manage:role:update:*
      - manage:role:update:enabled
      - manage:role:update:policy
      - manage:role:update:editPolicy
      - manage:role:update:actions
      - manage:role:update:key:*
      - manage:role:update:key:add
      - manage:role:update:key:remove
      - manage:role:update:user:*
      - manage:role:update:user:add
      - manage:role:update:user:remove
      - manage:role:history:tx:list
      - manage:identity:*
      - manage:identity:readonly
      - manage:identity:verify
      - manage:identity:add
      - manage:identity:remove
      - manage:identity:list
      - manage:org:*
      - manag

# --- truncated at 32 KB (62 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cubist/refs/heads/main/openapi/cubist-role-access-tokens-api-openapi.yml